Matrix CR Studio

NIST FIPS 203/204/205

PQC Migration

Before Q-Day.

We run ML-KEM-768 in our own self-hosted infrastructure. Your RSA and ECC keys are on borrowed time, and we've run the full Shor-ECDLP circuits on real IBM quantum hardware (public job IDs) to understand the threat first-hand. Key recovery was classical; we claim the execution, not a quantum break. We audit your cryptographic surface, score your Q-Day exposure, and ship a 3-phase migration roadmap you can execute against CNSA 2.0 deadlines.

Every assessment runs only against infrastructure you authorize in writing, from public and client-provided inputs. We scope to systems, never to individuals, and no probing begins before the engagement is signed.

START AN ASSESSMENTSEE THE HORIZON TABLE

The Problem

Harvest now. Decrypt later. Already underway.

Nation-state adversaries are storing your encrypted TLS traffic today. They are not waiting for Q-Day to collect, they are waiting to decrypt. The MOSCA theorem is brutal: if X (data shelf life) + Y (migration time) > Z (years until cryptographically relevant quantum computers), you are already too late.

NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) in August 2024. CISA and the NSA published CNSA 2.0 with hard transition deadlines for critical infrastructure. The federal question isn't whether to migrate, it is how fast you can prove you did.

Most vendors will sell you a framework document. We built and ran the full Shor-ECDLP attack circuit on real IBM quantum hardware, published every job ID, and audited our own result when the quantum signal didn't hold. We know the attack at the circuit level, and we tell you exactly where the science stands.

Q-Day Horizon Table

Which algorithms fall. When.

Derived from NIST IR 8547 §3.1 and the CNSA 2.0 timeline, plus our own real-hardware Shor-ECDLP execution on ibm_fez. Key recovery was classical, we claim the hardware execution, not a quantum break.

ALGORITHMHORIZONTIERNOTE
RSA-20488CRITICALHarvest-now window opens ~2030 · decrypt 2032+
RSA-409612HIGHLarger keys buy time · still falls to Shor
ECDSA-P2568CRITICALMatches RSA-2048 risk · signatures vulnerable
ECDH-P2568CRITICALKey exchange, highest HNDL exposure
ECDH-P38410HIGHCNSA 1.0 baseline · CNSA 2.0 replaces it
AES-25630+SAFEGrover halves effective strength · still 128-bit
SHA-25630+SAFEGrover halves preimage · 128-bit margin
ML-KEM-76850+TARGETFIPS 203 · Module-Lattice KEM · our default choice
ML-DSA-6550+TARGETFIPS 204 · Module-Lattice Digital Signature
SLH-DSA-128f50+TARGETFIPS 205 · Hash-based · stateless · conservative fallback

Cryptographic Surfaces

Ten surfaces. Every one audited.

Our assessment engine enumerates these ten cryptographic surface categories from your stack description and tags every algorithm by deployment context, key size, and exposure tier.

01

TLS / HTTPS

Certificate chains, session handshake, mutual auth

02

Code Signing

Firmware, package signatures, CI/CD artifacts

03

At-Rest Storage

Disk encryption, DB encryption keys, backup ciphers

04

Key Exchange

Diffie-Hellman, ECDH, wrapped session keys

05

Firmware

Boot chains, BMC, iLO, Redfish, signed updates

06

API Authentication

JWT, OAuth signing keys, HMAC + asymmetric

07

VPN

IPsec IKE, WireGuard static keys, OpenVPN

08

Email

S/MIME, PGP, DKIM signing

09

PKI

Root CAs, intermediate certs, revocation lists

10

HSM / Key Vault

Hardware-bound keys, rotation policy, attestation

Assessment Pipeline

Five phases. One assessment cycle.

01SEEDAsset ingestion

Supply your tech stack as a free-text description, asset inventory, or architecture diagram. An LLM-powered extractor parses your inputs with a regex fallback, works offline, works on napkin sketches.

02SCANCryptographic surface enumeration

Ten surface categories extracted and classified: TLS, code signing, storage, key exchange, firmware, API auth, VPN, email, PKI, HSM. Every asset tagged with its active algorithm, key size, and deployment context.

03SCOREQ-Day exposure scoring

Four-tier exposure model (CRITICAL / HIGH / MONITOR / SAFE) computed from NIST IR 8547 horizon tables, sector-specific data lifetime, and the MOSCA theorem X+Y+Z>T. Priority scores (0-100) rank every finding by urgency.

04ROADMAP3-phase migration roadmap

Phase 1: high-exposure key exchange and signing. Phase 2: at-rest and storage. Phase 3: archival and compliance tail. Every recommendation points to a specific FIPS 203/204/205 algorithm and CNSA 2.0 deadline.

05REPORTSigned report + audit trail

Report written to a cryptographically signed evidence database with a reproducible hash. Telegram digest. Every claim is re-derivable from the same inputs, an auditor can reproduce the finding without trusting us.

Empirical Proof

Not theorems. Hardware results.

10

Shor-ECDLP Circuits Run

ibm_fez · 0/10 quantum break · all raw data published

768

ML-KEM Parameter

FIPS 203 · self-hosted deployment

X+Y+Z

MOSCA Theorem

NIST IR 8547 §3.1

10

Crypto Surfaces

Automatic enumeration

What You Get

Four deliverables. One engagement.

Executive

Board-ready exposure summary

One-page CRITICAL / HIGH / MONITOR / SAFE breakdown with sector-specific data lifetime analysis. The artifact a CISO shows the audit committee.

Technical

3-phase migration roadmap

Per-surface migration plan with target algorithms, key sizes, rollout sequence, and deadline anchors to CNSA 2.0 and OMB M-23-02.

Compliance

NIST SP 800-227 documentation

Cryptographic inventory report in the exact format federal auditors ask for. Acceptable to DORA Art. 6, SWIFT CSP, ETSI GR-QSC-004 reviewers.

Operational

Self-hosted reference architecture

We run ML-KEM-768 in our own self-hosted infrastructure with cryptographic signing. You get the same reference implementation patterns we deploy ourselves.

Aligned Frameworks

Every roadmap maps to the source.

Each migration deliverable is anchored to the framework that mandates it. These links go straight to the issuing authority, verify the requirement yourself.

NSA · US

CNSA 2.0

CISA · US

Quantum-Readiness

OMB · US

M-23-02

NIST · US

IR 8547

NIST · US

SP 800-227

ENISA · EU

PQC Guidance

DORA · EU

Article 6 · ICT Risk

ETSI · EU

Quantum-Safe Crypto

SWIFT · Global

CSP / CSCF

BSI · DE

Migration to PQC

Get Started

Migrate before the
adversary decrypts.

Initial assessment in 5 business days. Full cryptographic inventory, Q-Day exposure score, and phase-1 migration plan.

Engagements scale with scope, from a focused assessment to a full enterprise migration. We run ML-KEM-768 in our own self-hosted infrastructure, ask us.

REQUEST ASSESSMENTTRY THE LIVE DASHBOARDREAD THE Q-DAY PROOF